CVE-2025-11145
7.5CBK Soft Software · enVision
The CBK Soft Software enVision platform contains an observable discrepancy vulnerability that allows for account footprinting and the unauthorized exposure of sensitive personal information.
Executive summary
An unauthenticated vulnerability in the CBK Soft Software enVision platform allows for account footprinting and the exposure of sensitive user data, posing a significant risk to information confidentiality.
Vulnerability
This vulnerability involves an observable discrepancy (CWE-203) that facilitates account footprinting, allowing an unauthenticated remote attacker to harvest sensitive or private personal information.
Business impact
The exposure of sensitive personal information can lead to severe privacy violations, potential regulatory non-compliance, and an increased risk of targeted social engineering or identity theft attacks against users. Given the CVSS score of 7.5, this high-severity flaw represents a significant risk to organizational data integrity and user trust.
Remediation
Immediate Action: Organizations should upgrade to enVision version 250566 or higher immediately to address the underlying logic discrepancy.
Proactive Monitoring: Security teams should monitor system access logs for unusual patterns of sequential account queries or mass enumeration attempts originating from single IP addresses.
Compensating Controls: Deploy a Web Application Firewall (WAF) to detect and block traffic patterns indicative of account enumeration or automated scraping of user identifiers.
Exploitation status
Public Exploit Available: No (exploit_available: false).
Analyst recommendation
The ability for an unauthenticated actor to perform account footprinting is a critical security failure that necessitates prompt remediation. Administrators must prioritize updating the enVision software to the patched release and verify that monitoring controls are in place to detect any attempts to leverage this information disclosure flaw.
Sources
Originally found and disclosed by Emre AKTAŞ, per the CVE Program record.